• Recent
    • Unsolved
    • Tags
    • Popular
    • Users
    • Groups
    • Search
    • Register
    • Login

    1.6 Migration via new Install with no DB Transfer

    Scheduled Pinned Locked Moved Unsolved FOG Problems
    fog 1.6clientagent1.6ca ssl
    2 Posts 2 Posters 23 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      Coolguy3289
      last edited by Coolguy3289

      I just did a massive overhaul on our fog service, migrating directly into 1.6 by running a new server from scratch rather than a database migration (there were some Foreign Key check failures on the in-place upgrade), and for the most part everything seems to be working except reliable agent communication. Both on the old and new agent I’m having a bitch of a time with the CA communication.

      When using the new agent from the GitHub, I get a 503 error, so referencing the apache error logs gives me a bit of insight:
      Got error 'PHP message: FOG agent enroll: signing for host 387 from 10.1.60.40 failed: the issued certificate does not verify against /opt/fog/snapins/ssl/CA/.fogCA.pem'

      In this instance, this was a fresh agent install, so I’m not sure what cert is being compared to what. I’m assuming until told otherwise that my FOG Generated PKI is foobar for production use, but I’m unsure of the steps to even take in this instance.

      Tom ElliottT 1 Reply Last reply Reply Quote 0
      • Tom ElliottT
        Tom Elliott @Coolguy3289
        last edited by Tom Elliott

        @Coolguy3289 Thanks for the log line. It points at a bug, not at your approach.

        The installer creates a “FOG Agent CA” under the server root CA. It only creates it when the file is missing. If the root CA changes later (for example, you copy the old server’s /opt/fog/snapins/ssl onto the new box so existing clients keep trusting it), the agent CA stays signed by the first root. Every enrollment then fails with the error you see, and the agent gets a 503.

        The fix is in PR #1810: the installer now re-creates the agent CA when the current root did not sign it.

        To fix your server now, without waiting for the PR:

        sudo grep PKI_AGENT_CA_CERT /opt/fog/.fog-pki
        

        Move the .fogAgentCA.pem and .fogAgentCA.key files in that directory to a backup location. Then re-run the installer. It creates a new agent CA under your current root, and enrollment works.

        You do not need your internal PKI for this. The FOG-generated root is fine for production.

        Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG! Get in contact with me (chat bubble in the top right corner) if you want to join in.

        Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

        Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

        1 Reply Last reply Reply Quote 0
        • 1 / 1
        • First post
          Last post

        65

        Online

        12.8k

        Users

        17.7k

        Topics

        157.2k

        Posts
        Copyright © 2012-2026 FOG Project